← Back to context

Comment by PaulCarrack

9 hours ago

Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.

Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them. Usually under ongoing attack, at least by professional phone cracking software vendors and secret services.

  • >Based on the artificial delays Google introduces into the Android patching process, on the general crappiness of mobile firmware and the sleaziness of major mobile chipset vendors, I think it's safe to assume that even if you are supposedly getting updates, there are unpatched zero-day vulnerabilities in them.

    Maybe if you include third party android OEMs like samsung, but google pixels are as up to date as you can get.

Android Security Bulletins don't list the vast majority of firmware, driver, HAL and especially Linux kernel vulnerabilities. Those list a large subset of the High and Critical severity Android Open Source Project (AOSP) vulnerabilities backported to older releases along with a tiny portion of non-AOSP vulnerabilities. AOSP vulnerabilities below High and Critical severity aren't backported so those aren't listed. Non-AOSP vulnerabilities for Pixels are covered in the Pixel Update Bulletins with many of those being vulnerabilities in components used by other devices. Each OEM is supposed to make their own equivalent to the Pixel Update Bulletins, but they aren't required to provide those updates to claim the latest patch level.